Skip to content

Sigma rule conversion #99

Closed Answered by thomaspatzke
thekarannayak asked this question in Q&A
Discussion options

You must be logged in to vote

For CrowdStrike there's a pySigma processing pipeline that converts the field namings, rewrites some values etc. to the CrowdStrike data schema. The Splunk backend then converts into a Splunk query. With Sigma CLI this can be done with:

sigma convert -p crowdstrike -t splunk <sigma rule dir or files>

There's no backend for Exabeam, also not for legacy sigmac.

Replies: 1 comment 6 replies

Comment options

You must be logged in to vote
6 replies
@thomaspatzke
Comment options

@thekarannayak
Comment options

@thekarannayak
Comment options

@thomaspatzke
Comment options

@thekarannayak
Comment options

Answer selected by thomaspatzke
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants